Skip to content

Suspicious Modifications to Windows Startup Registry Keys

This detection identifies potentially suspicious modifications to common Windows startup registry keys. Adversaries frequently abuse these registry locations for persistence, ensuring malicious executables run automatically at user logon or system startup. To reduce false positives, the rule filters out known legitimate processes, command lines, registry data, and file hashes via exclusion lists.

Detection details

Tactic Technique Author Date
Persistence T1547.001, Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder Rory Wagner (Sleuthifer) 2025-08-29

References

Placeholders to tune

exclusionList_IPCL, exclusionList_IPFN, exclusionList_RVD, exclusionList_IPSHA256 are placeholder lists. Fill in known-good values from your environment before you deploy this query.

Query

// List of startup registry keys to monitor
let startupRegistryList = dynamic([
  // HKEY_CURRENT_USER - User-specific autostarts
  'HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run',
  'HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RunOnce',
  'HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RunServices',
  'HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RunServicesOnce',
  'HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\Run',
  'HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Folders',
  'HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders',
  'HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Windows',
  // HKEY_LOCAL_MACHINE - Machine-wide autostarts
  'HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run',
  'HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RunOnce',
  'HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RunOnceEx',
  'HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RunServices',
  'HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RunServicesOnce',
  'HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\Run',
  'HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Folders',
  'HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders',
  // HKEY_LOCAL_MACHINE - Winlogon-related autostarts
  'HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\\Shell',
  'HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\\Userinit',
  // HKEY_LOCAL_MACHINE - Boot-level autostarts
  'HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Session Manager',
  // Wow6432Node - 32-bit app equivalents
  'HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run',
  'HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\RunOnce',
  'HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\RunOnceEx'
]);

// Exclusion lists to reduce false positives from known-good processes, commands, or registry data
let exclusionList_IPCL = dynamic(['ProcessCommandLineExclusions']);  // InitiatingProcessCommandLine exclusions
let exclusionList_IPFN = dynamic(['ProcessNameExclusions']);         // InitiatingProcessFileName exclusions
let exclusionList_RVD = dynamic(['RegistryValueExclusions']);        // RegistryValueData exclusions
let exclusionList_IPSHA256 = dynamic(['SHA256HashExclusions']);      // File hash exclusions
DeviceRegistryEvents
| where ActionType in ('RegistryValueSet', 'RegistryKeyCreated') 
  and tostring(RegistryKey) has_any (startupRegistryList)
| where not (tostring(InitiatingProcessCommandLine) has_any (exclusionList_IPCL))
| where not (tostring(InitiatingProcessFileName) has_any (exclusionList_IPFN))
| where not (tostring(RegistryValueData) has_any (exclusionList_RVD))
| where not (tostring(InitiatingProcessSHA256) has_any (exclusionList_IPSHA256))

View source on GitHub